Search

Found 16,960 results in 2118ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2020-1941 unknown FIX debian debian 6y ago Apache ActiveMQ webconsole admin GUI is open to XSS
CVE-2020-1953 unknown FIX debian debian 6y ago Remote code execution in Apache Commons Configuration
CVE-2019-14893 unknown FIX debian debian 6y ago Polymorphic deserialization of malicious object in jackson-databind
CVE-2019-14892 unknown FIX debian debian 6y ago Polymorphic deserialization of malicious object in jackson-databind
CVE-2020-10968 unknown FIX debian debian 6y ago jackson-databind mishandles the interaction between serialization gadgets and typing
CVE-2020-11111 unknown FIX debian debian 6y ago jackson-databind mishandles the interaction between serialization gadgets and typing
CVE-2020-12397 critical 9.5 FIX arch archdebian debian rhel 6y ago multiple issues in thunderbird
CVE-2020-6831 critical 9.5 FIX arch archdebian debian sles 6y ago A buffer overflow could occur when parsing and validating SCTP chunks in WebRTC. This could have led to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox ESR <…
CVE-2020-12395 critical 9.5 FIX arch archdebian debian rhel 6y ago Mozilla developers and community members reported memory safety bugs present in Firefox 75 and Firefox ESR 68.7. Some of these bugs showed evidence of memory corruption and we presume that with enoug…
CVE-2020-12392 critical 9.5 FIX arch archdebian debian rhel 6y ago The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP POST data of a request, which can be controlled by the website. If a user used the 'Copy as cURL' feature and past…
CVE-2020-12387 critical 9.5 FIX arch arch slesdebian debian 6y ago A race condition when running shutdown code for Web Worker led to a use-after-free vulnerability. This resulted in a potentially exploitable crash. This vulnerability affects Firefox ESR < 68.8, Fire…
CVE-2020-10969 unknown FIX debian debian 6y ago jackson-databind mishandles the interaction between serialization gadgets and typing
CVE-2020-11620 unknown FIX debian debian 6y ago jackson-databind mishandles the interaction between serialization gadgets and typing
CVE-2020-2773 critical 9.5 FIX slesdebian debian rhel 6y ago RHSA-2021:0736: java-1.8.0-ibm security update (Critical)
CVE-2020-6825 critical 9.5 FIX arch arch slesdebian debian 6y ago Mozilla developers and community members Tyson Smith and Christian Holler reported memory safety bugs present in Firefox 74 and Firefox ESR 68.6. Some of these bugs showed evidence of memory corrupti…
CVE-2020-6821 critical 9.5 FIX arch arch slesdebian debian 6y ago When reading from areas partially or fully outside the source resource with WebGL's <code>copyTexSubImage</code> method, the specification requires the returned values be zero. Previously, this memor…
CVE-2020-11100 critical 9.5 FIX arch arch slesdebian debian 6y ago arbitrary code execution in haproxy
CVE-2020-5275 unknown FIX debian debian 6y ago In symfony/security-http before versions 4.4.7 and 5.0.7, when a `Firewall` checks access control rule, it iterate overs each rule's attributes and stops as soon as the accessDecisionManager decides …
CVE-2020-5274 unknown FIX debian debian 6y ago In Symfony before versions 5.0.5 and 4.4.5, some properties of the Exception were not properly escaped when the `ErrorHandler` rendered it stacktrace. In addition, the stacktrace were displayed even …
CVE-2020-5255 unknown FIX debian debian 6y ago In Symfony before versions 4.4.7 and 5.0.7, when a `Response` does not contain a `Content-Type` header, affected versions of Symfony can fallback to the format defined in the `Accept` header of the r…
CVE-2020-6814 critical 9.5 FIX arch arch slesdebian debian 6y ago Mozilla developers reported memory safety bugs present in Firefox and Thunderbird 68.5. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these co…
CVE-2020-6812 critical 9.5 FIX arch arch slesdebian debian 6y ago The first time AirPods are connected to an iPhone, they become named after the user's name by default (e.g. Jane Doe's AirPods.) Websites with camera or microphone permission are able to enumerate de…
CVE-2020-6811 critical 9.5 FIX arch arch slesdebian debian 6y ago The 'Copy as cURL' feature of Devtools' network tab did not properly escape the HTTP method of a request, which can be controlled by the website. If a user used the 'Copy as Curl' feature and pasted …
CVE-2020-6807 critical 9.5 FIX arch arch slesdebian debian 6y ago When a device was changed while a stream was about to be destroyed, the <code>stream-reinit</code> task may have been executed after the stream was destroyed, causing a use-after-free and a potential…
CVE-2020-6806 critical 9.5 FIX arch arch slesdebian debian 6y ago By carefully crafting promise resolutions, it was possible to cause an out-of-bounds read off the end of an array resized during script execution. This could have led to memory corruption and a poten…
CVE-2020-6805 critical 9.5 FIX arch arch slesdebian debian 6y ago When removing data about an origin whose tab was recently closed, a use-after-free could occur in the Quota manager, resulting in a potentially exploitable crash. This vulnerability affects Thunderbi…
CVE-2019-20503 critical 9.5 FIX arch archdebian debian sles 6y ago usrsctp before 2019-12-20 has out-of-bounds reads in sctp_load_addresses_from_init.
CVE-2020-9546 critical 9.8 9.8 FIX debian debian rocky rhel fasterxmlnetapporacle 6y ago RHSA-2020:1644: pki-core:10.6 and pki-deps:10.6 security, bug fix, and enhancement update (Moderate)
CVE-2019-17569 unknown FIX debian debian 6y ago The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were …
CVE-2020-6795 critical 9.5 FIX arch archdebian debian rhel 6y ago multiple issues in thunderbird
CVE-2020-6794 critical 9.5 FIX arch archdebian debian rhel 6y ago multiple issues in thunderbird
CVE-2020-6793 critical 9.5 FIX arch archdebian debian rhel 6y ago multiple issues in thunderbird
CVE-2020-6792 critical 9.5 FIX arch archdebian debian rhel 6y ago multiple issues in thunderbird
CVE-2020-7238 unknown FIX slesdebian debian 6y ago HTTP Request Smuggling in Netty
CVE-2019-20444 unknown FIX slesdebian debian 6y ago HTTP Request Smuggling in Netty
CVE-2019-20445 unknown FIX slesdebian debian 6y ago HTTP Request Smuggling in Netty
CVE-2020-6800 critical 9.5 FIX arch arch slesdebian debian 6y ago Mozilla developers and community members reported memory safety bugs present in Firefox 72 and Firefox ESR 68.4. Some of these bugs showed evidence of memory corruption and we presume that with enoug…
CVE-2020-6798 critical 9.5 FIX arch arch slesdebian debian 6y ago If a template tag was used in a select tag, the parser could be confused and allow JavaScript parsing and execution when it should not be allowed. A site that relied on the browser behaving correctly…
CVE-2020-6796 critical 9.5 FIX arch arch slesdebian debian 6y ago A content process could have modified shared memory relating to crash reporting information, crash itself, and cause an out-of-bound write. This could have caused memory corruption and a potentially …
CVE-2019-17558 unknown 2.5 KEVEXP debian debian 6y ago The Apache Solr VelocityResponseWriter plug-in contains an unspecified vulnerability which can allow for remote code execution.
CVE-2019-10911 unknown FIX debian debian 6y ago In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, a vulnerability would allow an attacker to authenticate as a privileged user on sites with…
CVE-2019-10912 unknown FIX debian debian 6y ago In Symfony before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, it is possible to cache objects that may contain bad user input. On serialization or unserialization, this coul…
CVE-2019-11325 unknown FIX debian debian 6y ago An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrar…
CVE-2019-10172 unknown FIX debian debian 6y ago Improper Restriction of XML External Entity Reference in jackson-mapper-asl
CVE-2019-12422 unknown debian debian 6y ago Improper input validation in Apache Shiro
CVE-2019-17666 critical 9.5 FIX arch arch slesdebian debian 6y ago rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer overflow.
CVE-2019-10782 unknown FIX debian debian 6y ago XML external entity (XXE) processing ('external-parameter-entities' feature was not fully disabled))
CVE-2020-5397 unknown FIX debian debian 7y ago CSRF attack via CORS preflight requests with Spring MVC or Spring WebFlux
CVE-2020-5398 unknown FIX debian debian 7y ago RFD attack via Content-Disposition header sourced from request input by Spring MVC or Spring WebFlux Application
CVE-2019-17024 critical 9.5 FIX arch archdebian debian rhel 7y ago Mozilla developers reported memory safety bugs present in Firefox 71 and Firefox ESR 68.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…
CVE-2019-17022 critical 9.5 FIX arch archdebian debian rhel 7y ago When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer does not escape &lt; and &gt; characters. Because the resulting string is pasted directly into the text …
CVE-2019-17017 critical 9.5 FIX arch archdebian debian rhel 7y ago Due to a missing case handling object types, a type confusion vulnerability could occur, resulting in a crash. We presume that with enough effort that it could be exploited to run arbitrary code. Thi…
CVE-2019-17016 critical 9.5 FIX arch archdebian debian rhel 7y ago When pasting a &lt;style&gt; tag from the clipboard into a rich text editor, the CSS sanitizer incorrectly rewrites a @namespace rule. This could allow for injection into certain types of websites re…
CVE-2019-10219 unknown FIX debian debian 7y ago The SafeHtml annotation in Hibernate-Validator does not properly guard against XSS attacks
CVE-2019-17571 critical 9.8 9.8 FIX debian debian slesubuntu ubuntu apachenetapporacle 7y ago Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization ga…
CVE-2019-12418 unknown FIX slesdebian debian 7y ago When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration f…
CVE-2019-17563 unknown FIX slesdebian debian 7y ago When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The wind…
CVE-2019-11745 critical 9.5 FIX arch arch slesdebian debian 7y ago multiple issues in firefox
CVE-2019-17012 critical 9.5 FIX arch arch slesdebian debian 7y ago Mozilla developers reported memory safety bugs present in Firefox 70 and Firefox ESR 68.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…
CVE-2019-17011 critical 9.5 FIX arch arch slesdebian debian 7y ago Under certain conditions, when retrieving a document from a DocShell in the antitracking code, a race condition could cause a use-after-free condition and a potentially exploitable crash. This vulner…
CVE-2019-17010 critical 9.5 FIX arch arch slesdebian debian 7y ago Under certain conditions, when checking the Resist Fingerprinting preference during device orientation checks, a race condition could have caused a use-after-free and a potentially exploitable crash.…
CVE-2019-17008 critical 9.5 FIX arch arch slesdebian debian 7y ago When using nested workers, a use-after-free could occur during worker destruction. This resulted in a potentially exploitable crash. This vulnerability affects Thunderbird < 68.3, Firefox ESR < 68.3,…
CVE-2019-17005 critical 9.5 FIX arch arch slesdebian debian 7y ago The plain text serializer used a fixed-size array for the number of <ol> elements it could process; however it was possible to overflow the static-sized array leading to memory corruption and a poten…
CVE-2019-17632 unknown FIX debian debian 7y ago Unescaped exception messages in error responses in Jetty
CVE-2019-10913 unknown FIX debian debian 7y ago In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, HTTP Methods provided as verbs or using the override header may be treated as trusted inpu…
CVE-2019-18886 unknown FIX debian debian 7y ago An issue was discovered in Symfony 4.2.0 to 4.2.11 and 4.3.0 to 4.3.7. The ability to enumerate users was possible due to different handling depending on whether the user existed when making unauthor…
CVE-2019-18888 unknown FIX debian debian 7y ago An issue was discovered in Symfony 2.8.0 through 2.8.50, 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. If an application passes unvalidated user input as the file for which MIM…
CVE-2019-18889 unknown FIX debian debian 7y ago An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is rel…
CVE-2019-10212 unknown FIX debian debian 7y ago Potential to access user credentials from the log files when debug logging enabled
CVE-2019-10910 unknown FIX debian debian 7y ago In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, when service ids allow user input, this could allow for SQL Injection and remote code exec…
CVE-2019-10909 unknown FIX debian debian 7y ago In Symfony before 2.7.51, 2.8.x before 2.8.50, 3.x before 3.4.26, 4.x before 4.1.12, and 4.2.x before 4.2.7, validation messages are not escaped, which can lead to XSS when user input is included. Th…
CVE-2019-15903 critical 9.5 FIX arch archdebian debian sles 7y ago In libexpat before 2.2.8, crafted XML input could fool the parser into changing from DTD parsing to document parsing too early; a consecutive call to XML_GetCurrentLineNumber (or XML_GetCurrentColumn…
CVE-2019-11764 critical 9.5 FIX arch archdebian debian rhel 7y ago Mozilla developers and community members reported memory safety bugs present in Firefox 69 and Firefox ESR 68.1. Some of these bugs showed evidence of memory corruption and we presume that with enoug…
CVE-2019-11763 critical 9.5 FIX arch archdebian debian rhel 7y ago Failure to correctly handle null bytes when processing HTML entities resulted in Firefox incorrectly parsing these entities. This could have led to HTML comment text being treated as HTML which could…
CVE-2019-11762 critical 9.5 FIX arch archdebian debian rhel 7y ago If two same-origin documents set document.domain differently to become cross-origin, it was possible for them to call arbitrary DOM methods/getters/setters on the now-cross-origin window. This vulner…
CVE-2019-11761 critical 9.5 FIX arch archdebian debian rhel 7y ago By using a form with a data URI it was possible to gain access to the privileged JSONView object that had been cloned into content. Impact from exposing this object appears to be minimal, however it …
CVE-2019-11760 critical 9.5 FIX arch archdebian debian rhel 7y ago A fixed-size stack buffer could overflow in nrappkit when doing WebRTC signaling. This resulted in a potentially exploitable crash in some instances. This vulnerability affects Firefox < 70, Thunderb…
CVE-2019-11759 critical 9.5 FIX arch archdebian debian rhel 7y ago An attacker could have caused 4 bytes of HMAC output to be written past the end of a buffer stored on the stack. This could be used by an attacker to execute arbitrary code or more likely lead to a c…
CVE-2019-11757 critical 9.5 FIX arch archdebian debian rhel 7y ago When following the value's prototype chain, it was possible to retain a reference to a locale, delete it, and subsequently reference it. This resulted in a use-after-free and a potentially exploitabl…
CVE-2019-17359 unknown FIX debian debian 7y ago Out-of-Memory Error in Bouncy Castle Crypto
CVE-2019-17545 unknown FIX debian debian 7y ago GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.
CVE-2019-16869 unknown FIX slesdebian debian 7y ago HTTP Request Smuggling in Netty
CVE-2019-12402 unknown FIX debian debian 7y ago Denial of Service in Apache Commons Compress
CVE-2019-10753 unknown FIX debian debian 7y ago Incorrect Resource Transfer Between Spheres in eclipse-wtp
CVE-2019-12400 unknown FIX debian debian 7y ago Improper input validation in Apache Santuario XML Security for Java
CVE-2019-16137 unknown FIX debian debian 7y ago An issue was discovered in the spin crate before 0.5.2 for Rust, when RwLock is used. Because memory ordering is mishandled, two writers can acquire the lock at the same time, violating mutual exclus…
CVE-2019-10088 unknown FIX slesdebian debian 7y ago Allocation of Resources Without Limits or Throttling in Apache Tika
CVE-2019-10093 unknown FIX slesdebian debian 7y ago Allocation of Resources Without Limits or Throttling in Apache Tika
CVE-2019-10094 unknown FIX slesdebian debian 7y ago Allocation of Resources Without Limits or Throttling in Apache Tika
CVE-2019-10184 unknown FIX debian debian 7y ago Undertow Missing Authorization when requesting a protected directory without trailing slash
CVE-2019-14439 unknown FIX debian debian 7y ago Deserialization of untrusted data in FasterXML jackson-databind
CVE-2019-14379 unknown FIX slesdebian debian 7y ago Deserialization of untrusted data in FasterXML jackson-databind
CVE-2015-7559 unknown FIX debian debian 7y ago Improper Input Validation and Missing Authentication for Critical Function in Apache ActiveMQ
CVE-2019-0193 unknown 1.5 KEVFIX debian debian 7y ago The optional Apache Solr module DataImportHandler contains a code injection vulnerability.
CVE-2019-14204 critical 9.8 9.8 FIX slesdebian debian denx 7y ago An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_umountall_reply.
CVE-2019-14203 critical 9.8 9.8 FIX slesdebian debian denx 7y ago An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_mount_reply.
CVE-2019-14202 critical 9.8 9.8 FIX slesdebian debian denx 7y ago An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_readlink_reply.
CVE-2019-14201 critical 9.8 9.8 FIX slesdebian debian denx 7y ago An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: nfs_lookup_reply.
CVE-2019-14200 critical 9.8 9.8 FIX slesdebian debian denx 7y ago An issue was discovered in Das U-Boot through 2019.07. There is a stack-based buffer overflow in this nfs_handler reply helper function: rpc_lookup_reply.
CVE-2019-14199 critical 9.8 9.8 FIX slesdebian debian denx 7y ago An issue was discovered in Das U-Boot through 2019.07. There is an unbounded memcpy when parsing a UDP packet due to a net_process_received_packet integer underflow during an *udp_packet_handler call.